Topic: security recommendations
-
Patch Now: SonicWall Warns of Critical RCE Flaw in SMA 100 Devices
SonicWall warns of a critical remote code execution vulnerability (CVE-2025-40599) in SMA 100 series appliances, urging immediate patching due to active exploitation by attackers with admin access. A hacker group (UNC6148) is deploying the rootkit OVERSTEP on compromised devices, enabling data th...
Read More » -
Beware Fake PayPal Alerts: Hackers Steal Logins, Deploy Malware
A sophisticated cyberattack uses fake PayPal security alerts, starting with phishing emails and escalating through phone-based social engineering to install malware. Attackers abuse legitimate remote monitoring tools like LogMeIn Rescue and AnyDesk to gain persistent access, evading detection by ...
Read More » -
North Korea's IT Workers Expand Targets Beyond Tech and Crypto
North Korea's covert IT worker program has expanded beyond targeting American tech and cryptocurrency firms to now include a wide range of global industries such as finance, healthcare, and public administration, posing a significant international security threat. Over 130 DPRK-linked operatives ...
Read More » -
60,000 Redis Servers Exposed by Critical Security Flaw
A critical vulnerability (CVE-2025-49844) in Redis, rated 10.0 in severity, allows attackers to gain full control over servers by exploiting a flaw in the Lua scripting engine that has existed for 13 years. Approximately 60,000 publicly accessible Redis servers with no authentication are at direc...
Read More » -
How Your Router Tracks You Even Without Your Phone
Researchers have discovered that standard WiFi networks can identify individuals with near-perfect accuracy by analyzing unencrypted beamforming feedback signals, even when people are not carrying connected devices. This technology transforms everyday wireless infrastructure into an invisible sur...
Read More » -
Over 40,000 OpenClaw Instances Found Exposed Online
Over 40,000 publicly exposed OpenClaw AI instances have been discovered, granting attackers the same access to systems and data as the AI agent itself. Exploitation is active, with many instances linked to prior breaches and vulnerabilities, including critical remote code execution flaws that all...
Read More » -
48 Million Gmail Credentials Leaked Online
A database containing nearly 149 million login credentials, including an estimated 48 million Gmail accounts, was exposed online, compiled from past breaches and infostealer malware. The primary risk is credential stuffing attacks, where stolen usernames and passwords are used to access other acc...
Read More » -
NCSC Alerts Orgs to Vulnerabilities in Exposed Devices
The UK's National Cyber Security Center has launched a **Proactive Notifications service** pilot, which scans the public internet for vulnerabilities in UK-connected systems and alerts organizations with tailored advice to fix them. The service operates legally and sends communications only from ...
Read More » -
SonicWall VPN Breach: Hackers Exploit Stolen Credentials
Attackers breached over 100 SonicWall SSLVPN accounts using stolen credentials, with malicious activity detected from October 4th to at least October 10th by Huntress. The intrusions utilized previously compromised valid credentials, not brute-force methods, and involved network reconnaissance an...
Read More » -
Urgent: Patch Citrix Bleed 2 NetScaler flaw as exploits go public
A critical Citrix NetScaler vulnerability (CVE-2025-5777) allows attackers to steal session tokens by exploiting malformed login requests to dump memory contents, similar to last year's CitrixBleed flaw. The flaw arises from improper use of the snprintf function, leaking ~127 bytes of memory per ...
Read More » -
500 npm Packages Infected by Shai-Hulud Malware Leaking Secrets
Over 500 npm packages, including popular tools like Zapier and Postman, have been compromised by the Shai-Hulud malware, which steals developer secrets and uploads them to rapidly multiplying GitHub repositories. The attack uses trojanized versions of legitimate packages to inject malicious scrip...
Read More » -
State Actor Behind SonicWall Cloud Backup Hack
A state-sponsored threat actor breached SonicWall's cloud backup service using brute-force techniques, accessing all stored backup files through an API call in a sophisticated nation-state level operation. SonicWall confirmed that core products, internal systems, and customer infrastructures were...
Read More » -
AI Agent OpenClaw Tricked by Phishing, Exposes User Data
Phishing simulations that trick humans also successfully deceived AI agents, with an OpenClaw email agent exposing sensitive data like AWS credentials and CRM exports after falling for classic social engineering tactics. The agent failed identity verification in urgent operational requests even u...
Read More » -
Beware: Malicious Blender Files Spreading StealC Malware
A Russian-linked cyberattack is distributing the StealC V2 malware via weaponized Blender files on 3D model marketplaces, exploiting trusted platforms to infect users' systems. The malware uses Blender's Auto Run feature to execute malicious Python scripts, which fetch a loader that installs pers...
Read More » -
Critical Flaws Exposed in Smart Air Compressor
Smart air compressors like the CAT-10020SMHAD with MDR2i controllers offer digital convenience but introduce cybersecurity risks, including vulnerabilities that could disrupt operations or manipulate data. Security flaws identified include hardcoded Wi-Fi passwords, unencrypted HTTP communication...
Read More » -
Windows App-V Scripts Bypass Enterprise Defenses with Infostealer
A sophisticated malware campaign bypasses enterprise security by tricking users into running a command that abuses a legitimate Microsoft script (`SyncAppvPublishingServer.vbs`) to stealthily execute PowerShell, targeting high-value corporate systems. The attack relies on specific Windows environ...
Read More » -
Critical Flaws Found in Fluent Bit Logging Agent
Severe security vulnerabilities have been discovered in Fluent Bit, a widely used telemetry logging tool installed over 15 billion times, impacting core functions in banking, cloud, and SaaS environments. The flaws include input validation issues, tag manipulation, path traversal, buffer overflow...
Read More » -
New MacOS Malware 'DigitStealer' Targets Apple M2/M3 Chips
DigitStealer is a sophisticated malware targeting macOS systems with Apple M2 and M3 chips, disguising itself as legitimate tools like DynamicLake or Google Drive to trick users into installation. The malware employs a multi-stage delivery process, checking system location and hardware to avoid v...
Read More » -
Skuld Infostealer Exploits WSUS Flaw (CVE-2025-59287)
A critical remote code execution vulnerability (CVE-2025-59287) in Windows Server Update Services (WSUS) is being actively exploited, allowing attackers to install information-stealing malware on unpatched systems. The flaw stems from unsafe deserialization of untrusted data, enabling unauthentic...
Read More » -
Tenable Uncovers Critical Google Gemini AI Flaws That Risked User Data
Tenable Research uncovered three critical security flaws in Google's Gemini AI, known as the Gemini Trifecta, which allowed attackers to manipulate the AI and steal sensitive user data without direct system access. The vulnerabilities affected components like Gemini Cloud Assist, Search Personali...
Read More »